Commit Graph
100 Commits
Author SHA1 Message Date
CanbiZ (MickLesk) 42442ca968 Let steamcmd update itself before installing Satisfactory (#17526)
On the run in which steamcmd replaces itself, the app_update that follows fails
with 'Missing configuration', and the same command succeeds once it runs again.
A login-only run first takes that self-update out of the install and update.
2026-09-26 21:01:56 +02:00
CanbiZ (MickLesk) 0e28ea7fe1 Build the AudioMuse-AI noavx2 environment on Python 3.11 (#17528)
The noavx2 requirements pin numpy 1.23.5 and onnx 1.14.1, neither of which ships
a cp312 wheel, so on 3.12 uv built them from source: numpy fails without
distutils and onnx without cmake. Every noavx2 pin has a 3.11 wheel.
2026-09-26 21:01:46 +02:00
CanbiZ (MickLesk) 9db16c2073 Hold @lobehub/ui at 5.49 while LobeHub's stable release needs it (#17531)
@lobehub/ui 5.50.0 dropped NeuralNetworkLoading, and LobeHub 2.2.18 still imports
it through a ^5.47.0 range with lockfile: false, so every fresh build now fails.
Upstream moved off it on main; the pin only applies while package.json still asks
for a 5.4x range, so it stops on its own with the next stable release.
2026-09-26 21:01:28 +02:00
CanbiZ (MickLesk) 5127c85ca7 Keep Trilium updates on the server releases (#17525)
The repo also publishes web-clipper-v* releases, and whenever upstream marked one
of those as latest the update offered to replace the server with the browser
extension. A v prefix makes core pick the newest stable server release itself
instead of trusting that marking.
2026-09-26 20:54:46 +02:00
CanbiZ (MickLesk) 83a4addccd Generate the NPM admin config and repair certbot's venv on update (#17523)
2.16.0 ships production.conf only as a template that its s6 prepare step renders,
so installs outside Docker never listened on 81; render it on install, on update
while keeping a custom admin port, and on update for containers already stuck on
2.16.0. Certbot's upgrade died on a dist-info without RECORD, which pip's own
--ignore-installed hint does not clear, so drop such records before upgrading.
2026-09-26 20:51:17 +02:00
CanbiZ (MickLesk) dce092a0a4 Komodo: add KOMODO_HOST | fix broken spinner (#17481)
* Check Komodo actually started and point KOMODO_HOST at the container

* Stop Komodo hanging on an unclosed message block
2026-09-26 20:49:03 +02:00
CanbiZ (MickLesk)andpavlojs 91bccdacd3 Semaphore: fix BoltDB migration by pinning 2.18.30 (#17439)
* Fix Semaphore BoltDB migration

* Update ct/semaphore.sh

Co-authored-by: pavlojs <63199635+pavlojs@users.noreply.github.com>

---------

Co-authored-by: pavlojs <63199635+pavlojs@users.noreply.github.com>
2026-09-26 19:08:26 +02:00
CanbiZ (MickLesk) 89671ce007 Take the Obsidian version from the Ignis release tag (#17503)
Upstream renamed OBSIDIAN_VERSION in its Dockerfile to IGNIS_OBSIDIAN_PIN, so the
grep matched nothing - and under pipefail the assignment itself aborts, which is why
the fallback on the next line never ran. The tag already carries the pairing
(0.8.13+obsidian.1.13.7), so read it there and keep both Dockerfile keys as a
fallback.
2026-09-25 21:09:05 +02:00
CanbiZ (MickLesk) 28aa1bdbee Refactor: Umbrel OS VM (#17505)
Refactor Umbrel OS VM script to improve structure and readability. Update function calls and variable handling for better maintainability.
2026-09-25 21:08:49 +02:00
CanbiZ (MickLesk) d7a3386dab Docker-LXC: remove Portainer installation from install (#17493)
* Docker-LXC: remove Portainer installation from install

Removed Portainer installation prompts and related code.

* Remove Portainer installation instructions from docker.sh

Removed instructions for installing Portainer as an addon.
2026-09-25 11:09:54 +02:00
CanbiZ (MickLesk) 037e55256c Journiv: Serve Node Frontend and add HTTP Auth .env (#17479)
* Let Journiv start over plain HTTP

* Build the Journiv frontend

* Return to the project root before alembic
2026-09-24 22:20:12 +02:00
CanbiZ (MickLesk) 26c3bb9325 Declare the RomM filesystem structure required since 5.3.0 (#17480) 2026-09-24 22:19:52 +02:00
MickLesk c69359d704 rm unneeded link 2026-09-24 12:23:17 +02:00
MickLesk 04fd8481f5 quickfix ln in immich update, Fixes #17482 2026-09-24 11:29:18 +02:00
CanbiZ (MickLesk) b855a5782a Use apt_update_safe instead of aborting on a failed apt update (#17462) 2026-09-24 08:06:49 +02:00
CanbiZ (MickLesk) 572e9f6512 Give omniroute 4 GB for the npm install (#17461) 2026-09-23 17:58:47 +02:00
CanbiZ (MickLesk) 050e6a02b7 Refactor: Scanopy (#16797)
* scanopy: use prebuilt server binary, relax release profile for generate-fixtures

* scanopy: drop unneeded rust build, use committed UI fixtures

* scanopy: restore generate-fixtures build, ui/src/lib/data is gitignored and incomplete

* scanopy: serve the UI from the binary, drop the source build

Upstream confirmed in scanopy/scanopy#698 that scanopy-server-linux-*
has carried the built UI since v0.17.13, fixtures and service logos
included, served on the same port as the API. The release notes never
said so, which is why we kept building it.

That removes the source tarball, the Rust toolchain and
generate-fixtures, Node with npm ci and npm run build, and
SCANOPY_WEB_EXTERNAL_PATH. With the variable set to a directory that no
longer has an index.html, v0.17.14 and earlier refuse to start, so the
update deletes the line rather than leaving it. build-essential,
libssl-dev and pkg-config go too: the release binary is static-pie with
no INTERP segment, so it has no runtime library dependencies.

/opt/scanopy stays, now only for .env and oidc.toml, and the unit's
WorkingDirectory follows it out of the removed backend directory. Since
nothing wipes that directory any more, the config survives an update on
its own, which is the report upstream passed on of an update coming
back without SCANOPY_WEB_EXTERNAL_PATH and the server starting API-only.

The update keeps the running binary until the new one answers
/api/health and puts it back if it does not, so a bad release leaves a
working server instead of a stopped one.

check_for_gh_release now keys on scanopy-server, matching the version
file the binary deploy writes; the Scanopy key belonged to the tarball
that is gone. Existing containers run one extra update, then agree.

* Refactor scanopy-install.sh for server setup

Updated installation script to configure Scanopy server and removed daemon configuration section.

* Update service names from 'scanopy-server' to 'Scanopy'

* Fix case sensitivity in fetch_and_deploy_gh_release

* scanopy: make the rollback restore the whole old setup

The health check put the previous binary back but nothing else, and the
source tree it needs was already gone by then: the update deleted
/opt/scanopy/ui before starting the new server, and removed
SCANOPY_WEB_EXTERNAL_PATH from the env at the same time. A failed
health check therefore left the old binary running without the UI it
serves from disk, so the rollback produced an API-only server.

Back up the env file and the unit alongside the binary, restore all
three when the check fails, and delete the source tree only once the
new server has answered. Nothing the old version needs is removed
before the new one has proven itself.

* scanopy: name the deployed binary what the unit starts

singlefile mode writes the asset to <target>/<app name>:

  local target_file="$app"
  [[ "${USE_ORIGINAL_FILENAME:-false}" == "true" ]] && target_file="$filename"

so with the app renamed to Scanopy the binary lands at /usr/bin/Scanopy
while the unit starts /usr/bin/scanopy-server, and the service never
comes up on a fresh install. Rename it after the deploy, the same way
the daemon block already renames "Scanopy Daemon".

Keeping the app name is what matters here: it is also the version file
(~/.scanopy), and changing it would make every existing container
report an update it does not need.
2026-09-23 16:26:45 +02:00
CanbiZ (MickLesk) ab57fd7f94 Run Borg-UI with a single gunicorn worker (#17445) 2026-09-23 16:17:35 +02:00
CanbiZ (MickLesk) 743c0b6ac6 immich: keep geodata linked and the build deps present on update (#17438)
* immich: keep geodata linked and the build deps present on update

The update wipes $APP_DIR before redeploying, which takes the geodata
symlink the install created with it, and never puts it back. The app
then finds no reverse-geocoding data and the web UI does not come up.

The library recompile assumes headers that only reached the install
list later, so a container built before that fails at the first missing
one - LCMS2 in the reported case.

* immich: keep geodata linked and the build deps present on update

The update wipes $APP_DIR before redeploying, which takes the geodata
symlink the install created with it, and never puts it back. The app
then finds no reverse-geocoding data and the web UI does not come up.

The library recompile assumes headers that only reached the install
list later, so a container built before that fails at the first missing
one - LCMS2 in the reported case.
2026-09-23 16:13:54 +02:00
CanbiZ (MickLesk) 76b839b04c several scripts: let uv see the project before syncing it | refactor some scripts that use uv (#17436)
* Let uv see the project before syncing it

uv refuses to run when a project pins a required-version it does not
match, in either direction: RomM pins ==0.12.13, which fails against
both the 0.10.3 a container was built with and the 0.12.17 latest
installs.

UV_PROJECT_DIR points setup_uv at the project so it reads that pin. It
is a prefix like PYTHON_VERSION and UV_VERSION, and the call sits
directly under fetch_and_deploy: the project is on disk by then, and
the deploy has closed its message block, which setup_uv needs since it
opens one of its own. That is also the only call needed - nothing
between the old early call and the deploy uses uv or Python, so the two
collapse into one.

Two things found along the way:

UV_PYTHON was set as a command prefix on setup_uv in 14 places. setup_uv
reads PYTHON_VERSION, never UV_PYTHON, and a prefix assignment does not
outlive the call, so those pins did nothing. They now use
PYTHON_VERSION, which installs the interpreter they were asking for.

Five update scripts had no setup_uv at all while their install
counterpart pinned a Python version. They now carry the same pin.

immich is left out: it runs uv through sudo -u inside a retry loop.

* yubal: drop the uv 0.7.19 pin

The pin came in with the script and was never explained. uv 0.7.19 is
from 2025-07-02; yubal's uv.lock has carried revision 3 since at least
2025-12-27, and older uv refuses a newer lockfile revision. The script
runs uv sync --frozen, so there is no fallback.

yubal declares no required-version of its own, so latest is what it
gets - and if it ever pins one, that pin is now honoured.
2026-09-22 16:06:15 +02:00
CanbiZ (MickLesk) f212f93d89 Stop generating header filenames with a newline in them (#17435)
generate-app-headers.sh read APP with a plain grep -oP, so a script that
sets APP twice yielded both lines and the filename became
"almalinux
almalinux${var_version}vm". Three of those are in the tree
and they make main impossible to check out on Windows.

Nothing reads vm/headers: get_header fetches banners from the core
repo, which already carries clean almalinux, debian and ubuntu.
2026-09-22 14:30:44 +02:00
CanbiZ (MickLesk) 1ca4284ac3 truenas-vm: strip the G before the storage allocation (#17407)
storage:N wants a plain number; vm_prompt_disk_size returns 32G, so the
advanced path failed with "unable to parse zfs volume name '32G'".
2026-09-21 15:44:05 +02:00
CanbiZ (MickLesk) 7c6fb406f2 Ubuntu-VM: AIO | new core | performance | remove old wrappers (#17354)
* Ubuntu-VM: AIO | new core | performance | remove old wrappers

This script automates the creation of an Ubuntu virtual machine with configurable options such as version selection, cloud-init usage, and advanced settings.

* Delete vm/ubuntu2204-vm.sh

* Delete vm/ubuntu2404-vm.sh

* Delete vm/ubuntu2504-vm.sh
2026-09-19 07:24:14 +02:00
CanbiZ (MickLesk) 924caeefc7 crafty-controller: chown after restore_backup so restored data keeps crafty ownership (#17348) 2026-09-18 15:28:15 +02:00
CanbiZ (MickLesk) 60fda0a57b databasus, domain-monitor, poznote: chown after restore_backup so restored data keeps its owner (#17350) 2026-09-18 15:28:03 +02:00
CanbiZ (MickLesk) 0e359292ca alpine-vm: ask for the Cloud-Init credentials (#17355)
The default path set USE_CLOUD_INIT itself, so the username and
password dialogs were skipped; only the advanced path asked. The cloud
image sets no password, so the question is which credentials, not
whether. Same fix as almalinux-vm and fedora-vm.
2026-09-18 15:26:47 +02:00
MickLesk 78fbbe78ed Revert "Replace MinIO installation with Garage setup in plane-install.sh"
This reverts commit c673429c83.
2026-09-18 11:14:15 +02:00
MickLesk c673429c83 Replace MinIO installation with Garage setup in plane-install.sh 2026-09-18 11:12:11 +02:00
CanbiZ (MickLesk) 3e69c2ded5 pangolin: Bump to 1.23.0 (#17343)
* pangolin: pin 1.23.0

* pangolin: pin 1.23.0 in installer
2026-09-18 09:57:47 +02:00
CanbiZ (MickLesk) 46dfe21e68 suggestarr: keep the data where the app actually reads it (#17317)
* suggestarr: keep the data where the app actually reads it

The env file sets CONFIG_DIR=/opt/suggestarr_data and the service passes
it through, but SuggestArr never reads that variable. Its database
manager builds the path from the application directory:

  DB_PATH = os.path.join(BASE_DIR, 'config', 'config_files', 'requests.db')

so config.yaml, requests.db and secret.key live under /opt/suggestarr,
which the update wipes with CLEAN_INSTALL. Every update came back as a
fresh install.

Make config/config_files a symlink to /opt/suggestarr_data and lay it
down again after each deploy, since the deploy replaces it with a real
directory. Existing installs have their files copied across first, with
cp -an so anything already in the data directory wins.

CONFIG_DIR stays in the env file: it is inert today and costs nothing if
upstream starts reading it.

* suggestarr: let a failed migration stop the update

The || true was wrong and the review caught it. CLEAN_INSTALL wipes
/opt/suggestarr right after this copy, so swallowing a failure here
means the source is deleted with nothing carried across.

The guard was not even doing anything: cp -an exits 0 when it skips a
file that already exists in the target, which is the only case that
looked like it needed one. It only returns non-zero on a real failure,
which is exactly when the update has to stop - and it now stops before
the deploy, with the original data still in place.

  cp -an, target file exists  -> exit 0, continues
  cp -an, source missing      -> exit 1, ERR trap, aborts before deploy

2>/dev/null goes as well, so the reason is visible.
2026-09-18 08:43:49 +02:00
CanbiZ (MickLesk) 5555c6e404 Refactor: Oxicloud (#17338)
* refactor: streamline OxiCloud installation process by using prebuilt binaries

* oxicloud: take the prebuilt binary in the update too

Upstream now attaches musl tarballs to every release (AtalayaLabs/
OxiCloud#533), so the update no longer has to install a Rust toolchain
and Node and compile for up to 35 minutes. That compile is also what
broke #16216: a release whose source did not build left users with a
failed install and no way forward.

The tarball carries one top-level directory, which the deploy helper
strips, so the binary lands at /opt/oxicloud/oxicloud. The frontend is
baked into it, so the SPA build and OXICLOUD_STATIC_PATH both go; the
variable is commented out rather than removed, since a stale ./static
path would otherwise point at a directory that no longer exists.

migrate-nfc-filenames is gone as a separate binary - it is now a
subcommand, oxicloud migrate nfc-filenames - so the update removes the
old one. ffmpeg replaces build-essential: the server forks it for video
thumbnails and it is the one runtime dependency the musl build still
needs from the system.

Defaults drop to 2 CPU and 2048 MB, which were sized for the compile.

* oxicloud: install ffmpeg on update as well

The install gained it, the update did not, so a container created before
this change would never get it. The musl binary forks ffmpeg for video
thumbnails; without it that one feature stays silently unavailable.
2026-09-18 08:42:54 +02:00
CanbiZ (MickLesk) afbdf20aed immichframe: set the admin password the new admin UI requires (#17315)
* immichframe: set the admin password the new admin UI requires

immichFrame/ImmichFrame#698 added an admin UI that refuses to open
/admin unless IMMICHFRAME_ADMIN_PASSWORD is set, leaving users to edit
the unit by hand after an install or an upgrade from an older version.

Generate one, put it in the unit next to the other Environment lines,
and record it in ~/immichframe.creds the way the other scripts record
credentials. The update adds the line only when it is missing, so a
password already set by hand survives.

* immichframe: write the creds file the way the other scripts do

Sixty install scripts use cat <<EOF for their .creds file and exactly
one used an echo block, which was this one. Match the rest.

The install writes the file, the update appends: on an existing
container the file may already be there from the original install, and
the password line is only added when the unit has none.
2026-09-18 08:42:44 +02:00
CanbiZ (MickLesk) bb13cf5aea romm: make the library paths follow ROMM_BASE_PATH (#17279)
Upstream derives everything from one setting:

  ROMM_BASE_PATH = _get_env("ROMM_BASE_PATH", "/romm")
  LIBRARY_BASE_PATH = f"{ROMM_BASE_PATH}/library"

There is no separate library setting; config.yml's roms_folder is only
a folder name inside the library. So ROMM_BASE_PATH in /opt/romm/.env
is the single lever, and everything that names a path has to follow it.

Two places did not. The watcher unit had /var/lib/romm/library written
into ExecStart, so a moved library was still watched at the default and
rescans never fired. It now uses ${ROMM_BASE_PATH}/library, which
systemd expands from the EnvironmentFile the unit already loads.

The Angie alias was derived from the env file, but only while the
install or an update ran. Editing ROMM_BASE_PATH afterwards left the
internal /library/ location pointing at the old path, and since the
backend serves content through X-Accel-Redirect, every download and
every play returned 404 while scanning and metadata kept working.
Re-sync it from an ExecStartPre on angie, so a restart is enough.

Update installs both for existing containers and rewrites the watcher
unit in place.

Reported in #17263. The suggested fix there was to template the alias,
which the scripts already did; the gap was that nothing re-applied it.
2026-09-17 17:59:36 +02:00
CanbiZ (MickLesk) e24f6baa05 Debian-VM: Refactor | Support Debian 11, 12, 13 (#17325)
* Debian-VM: Refactor | Support Debian 11, 12, 13

* remove deprecated debian 13 vm

* Update Debian VM script to use architecture variable (arm64 support)
2026-09-17 14:15:45 +02:00
CanbiZ (MickLesk) ba87729be7 sparkyfitness: run the Better Auth migration during the update (#17318)
* sparkyfitness: run the Better Auth migration during the update

1.7.1 ships a Better Auth version whose schema has columns 1.6.5 never
created, and nothing in the update adds them. The backend starts, then
refuses every sign-in:

  Database schema mismatch
    Missing columns session.impersonated_by two_factor.verified ...
    Run `npx auth migrate` to add the missing tables and columns.

Run exactly that after the backend dependencies are in place, with the
config Better Auth looks for, SparkyFitnessServer/auth.ts, and the
database credentials from /etc/sparkyfitness/.env. Users who hit this
were left running the server by hand to get the columns created.

A failure warns instead of aborting: the rest of the update has already
succeeded at that point, and the message names the remaining step.

* sparkyfitness: start the server through the entrypoint that migrates

The Better Auth CLI added in the previous commit is the wrong tool. It
generates sso_provider.user_id as text and cannot reference this
schema's uuid user.id:

  foreign key constraint "sso_provider_user_id_fkey" cannot be
  implemented [...] incompatible types: text and uuid

The real cause is one line up in the unit. It ran

  tsx SparkyFitnessServer.js

which imports the application module directly and never applies the
schema migrations. Upstream starts through index.ts - nodemon.json has
exec: tsx index.ts - and that file runs applyMigrations() and
applyRlsPolicies() before importing anything, with a comment naming this
exact failure:

  Better Auth validates the database schema eagerly, the moment
  betterAuth() is constructed at auth.ts module scope [...] When
  migrations ran later (from inside SparkyFitnessServer.ts) that check
  read the pre-migration schema on the first boot after an upgrade, so
  every /api/auth request failed until the container was restarted.

Point both the install and the update at index.ts and drop the CLI call.
index.ts exits non-zero when a migration fails, so systemd surfaces that
instead of serving a broken login.
2026-09-17 13:39:36 +02:00
CanbiZ (MickLesk) 251fd0b6b8 poznote: follow init.sh into docker/ (#17316)
6.87.0 moved init.sh from the repository root to docker/init.sh, so the
update stopped at

  chmod: cannot access '/opt/poznote/init.sh': No such file or directory

The file itself is byte for byte the same and uses absolute paths only,
so running it from the new location changes nothing. Prefer docker/ and
fall back to the old path, since a container pinned to an older release
still has it there.
2026-09-17 10:27:19 +02:00
CanbiZ (MickLesk) 556b9c4653 pocketbase-bot: accept the var_ names and two missing fields (#17305)
* pocketbase-bot: accept the var_ names and two missing fields

cpu, ram, hdd, os and version were already reachable, but only under
the PocketBase names. People type what the ct scripts call them, so
"/pocketbase <slug> var_ram=4096" was rejected as an unknown field
while "ram=4096" worked. The bot already carried the mapping as
RESOURCE_TO_CT_VAR, for display only.

Normalise the keys in parseKVPairs, so both the field=value path and
the method path accept them, along with disk and memory as the other
two names people reach for. Matching is case-insensitive.

pin_reason and last_update_commit exist on the record and are worth
editing, but were not in ALLOWED_FIELDS. slug, script_created and
script_updated stay out: the first is the key the command looks the
record up by, the other two belong to the timestamp workflow. notes and
install_methods keep their own subcommands.

* pocketbase-bot: write the sync PR against the PR template

The sync PR body had its own Summary and Source headings, so the
autolabeler found none of the template checkboxes it looks for and the
PR came out with nothing but "needs triage". It also never referenced
the issue the command came from.

Write the body the way the template expects, with the Website update
box ticked, which is what a PocketBase sync is. Tested thoroughly stays
unticked and Tested on says not tested, because nothing here was run;
close-invalid-pr-template skips bot authors, so that costs nothing.

Reference the triggering number as Fixes when the command came from an
issue and as a plain mention when it came from a PR comment, where
Fixes would point the PR at itself. issue_comment carries both under
github.event.issue, so the new IS_PR_COMMENT tells them apart.

* ci: stop the .app header PR being closed as a new script

allowedBots carried "community-scripts-pr-app" but not the
"[bot]"-suffixed name GitHub actually reports, and the check is an exact
match, so the exemption never applied to it. push-app-to-main is listed
both ways; this one was not. PR #17304 was closed as an untested new
script submission because of it.

generate-app-headers.sh empties ct/headers, tools/headers and
vm/headers and writes them again, so every run reports those files as
added. That is what the autolabeler's new-script rule looks for, and
the vm rule matched vm/headers too. Exclude the header directories from
both, and skip them in the close workflow's own added-file fallback, so
the label cannot come back by another route.

Checked against minimatch with the shipped config: header files get
neither label, ct/*.sh, install/*.sh and vm/*.sh still get theirs.

* pocketbase-bot: label the sync PR as a bugfix

The sync corrects CT defaults that no longer match the PocketBase
record, so bugfix describes it better than website update, which is
meant for metadata changes on the site itself.
2026-09-16 13:27:27 +02:00
CanbiZ (MickLesk) b4684b2faf Frigate: Bump to 0.18.0 (#17273)
* frigate: move to 0.18.0

Bump the pinned release and follow the four build changes that matter
outside of Docker.

ffmpeg: 0.18 ships 8.0 as the default and keeps 7.0 and 5.0 alongside
it, so /etc/frigate.env has to name all three or the s6 run script
resolves a version that install_deps.sh never downloaded.

go2rtc: pin to v1.9.14, the version the Dockerfile fetches. "latest"
happened to work but shipped whatever AlexxIT had tagged that day
rather than the build Frigate was tested against.

OpenVINO: requirements-ov.txt dropped tensorflow and openvino-dev, and
build_ov_model.py no longer uses the Model Optimizer. omz_tools is
therefore gone, which left the first two branches of the labelmap
lookup dead; download coco_91cl_bkgr.txt the way the Dockerfile does.

Intel media driver: 0.18 builds intel-media-va-driver-non-free from
source for Battlemage, because the prebuilt noble/trixie packages need
a glibc that bookworm does not have. Run it before install_deps.sh, as
the deps-rootfs stage does, and drop the jammy repo the build adds so
the later trixie pull for libva2 is not resolved against it.

The remaining build scripts and requirement files changed too, but
those come from the checked-out tree and follow the version bump on
their own.

* frigate: stop the detector config from replacing the base config

The install wrote a config with mqtt, cameras, auth and detect, then the
detector branch wrote the file again instead of adding to it. Both
branches used a single redirect, so everything above them was discarded
and the result had neither mqtt nor cameras. frigate/config/config.py
declares both as Field() without a default, in 0.17.2 as well as in
0.18.0, so Frigate rejected the file and came up in safe mode:

  mqtt - Field required
  cameras - Field required

Move hwaccel_args into the base block, since both branches set it, and
append the detector and model sections instead of overwriting.

Checked by generating both branches and parsing the result: the OpenVINO
path yields auth, cameras, detect, detectors, ffmpeg, model, mqtt, the
CPU path the same without detectors, and the test camera survives in
both.

* frigate: write the config in one place

Only the detector and model section depends on the CPU check, but the
file was assembled in three heredocs writing to the same path. That
shape is what produced the safe-mode config: both branches used a plain
redirect and discarded everything above them.

Pick the variable part into DETECTOR_CONFIG first and write the file
once, so the layout is visible in one block and no branch can replace
what came before it.

Output is unchanged, verified by generating both branches from the
previous commit and from this one and diffing: byte-identical.

* Update default RAM and disk values in frigate.sh
2026-09-16 12:01:52 +02:00
CanbiZ (MickLesk) 8050ec7af1 navidrome: repair root-owned data folders left by 0.61.x (#17275)
Navidrome 0.61.x created cache, artwork and plugins under the data
folder whenever any navidrome command ran, including the ones the deb
postinstall runs as root. 0.62 stopped creating them that way but never
corrected the owner, so a container that passed through 0.61.x carries a
root-owned artwork directory. 0.64.0 is the first release to write into
it and fails with

  writing image store: mkdir /var/lib/navidrome/artwork/hashed:
  permission denied

which breaks newly resolved album covers and every playlist cover, since
those are composites.

Repair the three directories the same way navidrome/navidrome#6143 does:
the entries themselves only, since they were created empty, real
directories owned by root only, and chown -h, because the navidrome user
owns the data folder and could otherwise plant a symlink.

The trailing || true is not in the upstream copy and is needed here.
Their postinstall runs without set -e, while update_script runs under
catch_errors, which sets -Ee with an ERR trap. find exits 1 as soon as
one starting point is missing, so on a container without a plugins
directory the update would abort.

Fixes the report in #17247, confirmed there by the reporter's stat and
dpkg log: artwork is root-owned and dated to their 0.60.3 -> 0.61.1
upgrade.
2026-09-16 12:01:42 +02:00
CanbiZ (MickLesk) b17e8e5abf Refactor: HomeAssistant-OS (core / improve functions / performance) (#17281)
* HomeAssistant-OS (VM): Refactor for improved readability

Refactor script to improve readability and maintainability. Updated function calls and variable assignments for better clarity.

* Modify author line in haos-vm.sh

Updated author information in the script header.

* Refactor Home Assistant OS version selection and caching

Refactor advanced settings dialog for Home Assistant OS version selection and simplify image caching logic.
2026-09-16 12:01:34 +02:00
CanbiZ (MickLesk) f5d336cfed tor-snowflake: read the Go version from the module root (#17276)
* tor-snowflake: read the Go version from the module root

Snowflake is a single Go module with go.mod at the repository root, not
under proxy/. The install read /opt/tor-snowflake/proxy/go.mod, which
has never existed, so grep failed and the version came out empty. Go
was then fetched from

  https://go.dev/dl/go.linux-amd64.tar.gz

with no version in the name, and the install aborted at that download.

Read the directive with a single awk instead of grep piped into awk.
The pipeline tripped catch_errors, which sets -Ee with pipefail and an
ERR trap, the moment the file was missing; that is the "exit code 2
while executing command awk" line that preceded the download failure.

Fall back to latest when the file cannot be read, so a future upstream
move of go.mod costs a Go version that is newer than the one pinned
rather than a failed build. setup_go already resolves latest, and also
resolves a bare major.minor to its newest patch, so a go directive
without a patch level stays fine.

Verified against v2.14.1: go.mod sits at the root and declares go
1.24.0, and the awk yields 1.24.0 from it and latest from a missing
file without tripping the ERR trap.

* Refactor GO_VERSION extraction in tor-snowflake.sh

Updated the method of extracting GO_VERSION from go.mod and set a default value if not found.
2026-09-16 11:59:19 +02:00
CanbiZ (MickLesk) 79a320fc3a Refactor: TrueNAS VM (core / improve functions / performance) (#17277)
* Refactor: TrueNAS VM (core / improve functions / performance)

* Boot TrueNAS from sata0, the disk it actually installs to

The boot order named scsi0, which never exists: the system disk is
sata0, and imported passthrough disks start at scsi1 because SCSI_NR is
pre-incremented. So the order always fell through to ide2 and the
installer came back up after every reboot.

* Fix URL in truenas-vm.sh script
2026-09-16 11:59:11 +02:00
CanbiZ (MickLesk) 8b01d1c302 docmost: stop corepack asking for confirmation during the build (#17282)
Docmost pins its package manager, so running pnpm goes through corepack,
which asks before fetching the pinned version:

  Corepack is about to download .../pnpm-11.25.0.tgz
  ? Do you want to continue? [Y/n]

The pnpm calls run under $STD, so with verbose off the question is
never shown and the update sits on "Configuring Docmost" waiting for an
answer nobody can see. With verbose on the same update completes,
because the prompt is visible and gets answered, which is exactly what
the reporter observed.

Set COREPACK_ENABLE_DOWNLOAD_PROMPT=0 before the pnpm calls in both the
install and the update, the way fifteen other ct scripts and ten
install scripts already do.
2026-09-16 11:59:00 +02:00
CanbiZ (MickLesk) fbea9c04c3 monitor-all: decide on flag values, not on key presence (#17261) 2026-09-15 09:16:12 +02:00
CanbiZ (MickLesk) be0a8c3467 Add --no-sync to Paperless uv run services (#17210) 2026-09-12 22:10:47 +02:00
CanbiZ (MickLesk) 764e4232ba Docker VM: Feature Bump - Refactor script for improved functionality (#17216) 2026-09-12 22:10:00 +02:00
CanbiZ (MickLesk) 0a48435ef9 poznote: serve from src/public docroot (#17187) 2026-09-12 12:01:26 +02:00
CanbiZ (MickLesk) 24e006cd81 calibre-web: use calibreweb release identifier to avoid version file collision (#17186) 2026-09-12 08:31:29 +02:00
MickLesk 10ab064f26 formatting fix issue report 2026-09-11 08:37:28 +02:00
CanbiZ (MickLesk) 73a8c55c9d passwordpusher: restore data before running migrations (#17141) 2026-09-11 07:43:04 +02:00
CanbiZ (MickLesk) de9b2f7ff3 paperclip: install the rust toolchain needed by the runner build (#17142) 2026-09-11 07:42:37 +02:00
CanbiZ (MickLesk) c001360b2d Rename lxc-delete.sh to guest-delete.sh (#17152) 2026-09-11 07:42:12 +02:00
CanbiZ (MickLesk) 785d33be40 core.func: fall back to a usable HOME when the shell has none (#17154) 2026-09-11 07:41:44 +02:00
CanbiZ (MickLesk) e253713148 homepage: run next directly instead of through pnpm (#17155) 2026-09-11 07:41:21 +02:00
CanbiZ (MickLesk) 7304dec635 update-apps: rewrite the retired Gitea base in every container before updating it (#17156) 2026-09-11 07:40:57 +02:00
CanbiZ (MickLesk) 28c18b735b issue template: add PVE release, execution context and phase; refresh distro list (#17160) 2026-09-11 07:40:36 +02:00
MickLesk 902b341327 Merge branch 'main' of https://github.com/community-scripts/ProxmoxVE into feat/guest-delete-vms 2026-09-10 10:39:42 +02:00
MickLesk cca5e8320a lxc-delete: also delete VMs, not just containers
One checklist now lists containers and VMs side by side, each tagged with its
type, with separate ALL CT / ALL VM entries. VMs stop via qm stop and are
removed with qm destroy --purge --destroy-unreferenced-disks.

Two fixes fall out of the rework: the destroy exit status is read from the
background job rather than from the spinner, so failures actually surface, and
a guest is only stopped once its deletion is confirmed.
2026-09-10 10:38:39 +02:00
CanbiZ (MickLesk) 810a6d2e82 vm: drop the discussions link from the summary (#17117) 2026-09-09 19:54:30 +02:00
MickLesk afff8c91cd Omada: resolve libssl1.1 from the Debian pools instead of a pinned URL
bullseye left security.debian.org when its LTS ended, so the hardcoded
libssl1.1_1.1.1w-0+deb11u8 filename now 404s. Scan the security, the
security-archive and the archive pools and take the newest build on offer
for the host architecture.

Closes #17104
2026-09-08 16:44:04 +02:00
CanbiZ (MickLesk) a3c029c341 Update Jellyfin FFmpeg dependency to version 8 (#17109) 2026-09-08 10:28:42 +02:00
CanbiZ (MickLesk) c039a297b3 flatnotes: follow upstream move to uv and Python 3.13 (#17090) 2026-09-07 16:37:07 +02:00
MickLesk b99dab130c node drift: label bump PRs so they reach the changelog 2026-09-07 14:25:44 +02:00
CanbiZ (MickLesk) 653341829f github: Open per-script Node bump PRs (#17065) 2026-09-07 12:53:38 +02:00
CanbiZ (MickLesk) 9e42f4b4a8 netboot-xyz: add Secure Boot and Legacy assets (#17066) 2026-09-07 12:52:48 +02:00
CanbiZ (MickLesk) dfb33d9559 heimdall: set up PHP 8.4 on update, keep only the database, run migrations (#17067) 2026-09-07 12:52:27 +02:00
CanbiZ (MickLesk) 7deac8444e reactive-resume: repair any wrong WorkingDirectory on update (#17068) 2026-09-07 12:52:04 +02:00
CanbiZ (MickLesk) f6185c0b1d mediamtx: keep mediamtx.yml across updates (#17069) 2026-09-07 12:51:42 +02:00
CanbiZ (MickLesk) 960e50f428 omnitools: allow remote action while npm ci (#17070) 2026-09-07 12:51:24 +02:00
CanbiZ (MickLesk) d4771cbf98 authentik: scope blueprints chown to avoid recursing into the mp0 bind mount (#17008) 2026-09-05 22:41:58 +02:00
CanbiZ (MickLesk) 535f2f2d2e iventoy: run iventoy.sh with bash instead of dash (#17034) 2026-09-05 22:41:32 +02:00
CanbiZ (MickLesk) 166c798e35 frigate: restart go2rtc.service before frigate starts (#17035) 2026-09-05 22:41:14 +02:00
CanbiZ (MickLesk) 89f179e05e snapotter: seed AI venv base packages on arm64, warn amd64 has no working CPU bundle (#16903) 2026-09-05 13:04:53 +10:00
CanbiZ (MickLesk) 9c750ffaf5 update-apps: follow renamed ct/ scripts instead of erroring out (#16991)
A container keeps the slug it was built with, so a renamed ct/ script leaves
the updater looking for a name that no longer exists.

Reported for pbs, renamed to proxmox-backup-server in 0e5f663df. The Alpine
merge on 2026-08-18 retired 29 more names the same way, so every container
installed from an alpine-* script before that date hits this too.

Candidates are only accepted when the target script really exists, so an
unknown slug still errors rather than running some other app's updater.

Fixes #16989
2026-09-05 13:04:27 +10:00
CanbiZ (MickLesk) d9c276c49c tolgee: bump required JDK from 21 to 25 (#17005) 2026-09-05 13:03:57 +10:00
CanbiZ (MickLesk) cfb0bfe4ac Refactor FileFlows: Stop Spinner before read -rp / Switch from "Node" to "Agent" (#17007)
* FileFlows Node: Stop Spinner before read -rp

* fileflows: update install path for Node->Agent rename, detect service unit dynamically

* fileflows: tolerate no pre-existing fileflows units when checking for the new Agent unit
2026-09-05 13:03:40 +10:00
CanbiZ (MickLesk) 1d1fd98d05 romm: write real version into backend/__version__.py placeholder (#17009) 2026-09-05 13:02:40 +10:00
CanbiZ (MickLesk) c272987bad Fix npm v12 allow-git/allow-remote restrictions across affected scripts (#17014)
* bentopdf: allow remote npm dependency for xlsx under npm v12

* librechat: allow remote npm dependency for xlsx under npm v12

* pangolin: allow remote npm dependencies for iron-remote-desktop packages under npm v12

* baserow: allow remote npm dependency for xlsx under npm v12

* cryptpad: allow git-based npm dependencies for drawio and json.sortify under npm v12
2026-09-04 17:52:31 +02:00
CanbiZ (MickLesk) 15b457b46d romm: allow git-based npm dependency for rom-patcher under npm v12 (#16990) 2026-09-03 16:04:50 +02:00
CanbiZ (MickLesk) d1855048f0 Pin Go to the version each project declares in go.mod (#16976) 2026-09-03 15:45:59 +02:00
CanbiZ (MickLesk) 68b5d96f64 Enhance backup process in teddycloud.sh (#16946) 2026-09-02 16:31:00 +02:00
CanbiZ (MickLesk) 65e5c87a33 Scripts: use shared core bootstrap for final 114 Script Batch (#16953)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.

versitygw.sh additionally gains a trailing newline; it lacked one.

With this batch every ct/ script is on the core engine.
2026-09-02 21:37:36 +10:00
CanbiZ (MickLesk) be84c3e1c1 Scripts: use shared core bootstrap for next 115 Script Batch (#16952)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.
2026-09-02 13:18:14 +02:00
CanbiZ (MickLesk) 277c782191 Scripts: use shared core bootstrap for next 115 Script Batch (#16951)
Replaces the misc/build.func bootstrap with the two-root core loader.
No other change: the engine contract (var_*, update_script, start,
build_container, description) is identical on both engines.
2026-09-02 21:14:48 +10:00
CanbiZ (MickLesk) f257cfdf89 Scripts: use shared core bootstrap for next 100 Script Batch (#16950) 2026-09-02 11:40:00 +02:00
CanbiZ (MickLesk) 1a06e9628c Move the next 25 scripts onto the core engine (#16934)
The 25 most-installed ct scripts still on misc/build.func, by install
count: homarr, influxdb, sonarr, radarr, networkoptimizer, authentik,
stirling-pdf, seerr, prowlarr, searxng, wordpress, zabbix, omada,
homeassistant, pegaprox, crafty-controller, iventoy, homelable,
flaresolverr, metube, netbird, casaos, obsidian-livesync, npmplus,
wazuh. ProxmoxVE goes from 115 migrated to 140.

Same three checks as #16749, since "migrate" has meant more than a line
swap before:

  - None of the 25 has an alpine-* variant, so there is no merge to do.
  - None references misc/ outside its bootstrap line.
  - Two functions exist only in misc/ (_gl_asset_urls,
    _send_abort_telemetry) and none of the 25 calls either.

So it is one line per script. Every head is byte-identical to the ones
migrated earlier, each diff is exactly 3+/1-, and all 25 parse.

Worth watching: scanopy is not in this set but sits at 32.9% success,
and casaos at 49.4% and networkoptimizer at 48.6% are in it. If those
two move, the engine is one changed variable among others.
2026-09-01 13:28:55 +02:00
CanbiZ (MickLesk) 97a36be502 jellyfin: verify repo suite via fallback chain and use ensure_dependencies for clearer apt failures (#16916) 2026-09-01 07:45:58 +02:00
MickLesk 75d33e16bd gh action: fix appid 2026-08-31 21:59:27 +02:00
MickLesk 535823a0fa Merge branch 'main' of https://github.com/community-scripts/ProxmoxVE 2026-08-31 21:58:11 +02:00
MickLesk 165c337c48 Use a distinct name for the PR app, which is not the header generator
vars.APP_ID named two different apps: 1065612 (community-scripts-pr-app)
here, 1108144 (app-header-generator) in ProxmoxVED. Folding both into
one GHAPP_HEADERS_ID would have pointed this repo at the wrong app, so
the PR app gets its own name.
2026-08-31 21:58:09 +02:00
CanbiZ (MickLesk) 3bb92c5a54 omv: migrate to new package repo host (packages.openmediavault.org is dead) (#16918) 2026-08-31 18:37:10 +02:00
CanbiZ (MickLesk) 6a5a714d18 openwebui: add UV_HTTP_TIMEOUT and retry loop to prevent uv install hangs (#16917) 2026-08-31 18:36:40 +02:00
CanbiZ (MickLesk) 8639310cfa Rename CI credentials to org-wide names, demote non-secrets to variables (#16919) 2026-08-31 18:35:56 +02:00
CanbiZ (MickLesk) 82dc3a6dec vaultwarden: relax cargo release profile via env vars to avoid build OOM (#16915) 2026-08-31 16:30:47 +02:00
CanbiZ (MickLesk) ea798df13a yuvomi/aurral: bump NODE_VERSION per upstream requirements (#16913) (#16914) 2026-08-31 16:30:11 +02:00
CanbiZ (MickLesk) d9eb574517 bambuddy: force asyncio loop, uvloop breaks camera proxy handlers (#16904) 2026-08-31 13:40:34 +02:00
CanbiZ (MickLesk) 82ee37f846 kima-hub/maintainerr/planka/spliit: bump NODE_VERSION (#16905) 2026-08-31 13:38:45 +02:00
CanbiZ (MickLesk) 6cae1ed744 bookorbit: raise service start timeout, migration can exceed systemd default (#16860) 2026-08-31 09:41:09 +02:00
CanbiZ (MickLesk) cecd3222fc filebrowser-quantum: strip removed disableIndexing key on update, restart service (#16892) 2026-08-31 09:40:58 +02:00
CanbiZ (MickLesk) b1edc2722d gatus: pin Go to gatus's go.mod version, modernize Alpine path to shared helpers (#16893) 2026-08-31 09:40:55 +02:00